Cybersecurity Engineer II
Indexed description
Duties And Responsibilities
- Support the design, implementation, and ongoing operation of security controls across the organization's cloud environments, with a primary emphasis on AWS and additional coverage of Microsoft Azure and Microsoft 365.
- Administer, configure, and optimize a cloud-native application protection platform such as Wiz to continuously discover cloud assets, identify misconfigurations, excessive permissions, exposed data, and vulnerable workloads, and surface findings for triage.
- Perform risk-based analysis and prioritization of cloud security findings using severity, exploitability, data sensitivity, and business context, and drive remediation to closure in partnership with cloud, infrastructure, application, and vendor teams.
- Evaluate cloud environments against recognized benchmarks and best practices—such as the CIS Benchmarks, the AWS Well-Architected Framework security pillar, and internal standards—and track configuration drift and remediation over time.
- Support cloud identity and entitlement security, including the review and right-sizing of AWS IAM roles, policies, and permission boundaries, and the reduction of standing and excessive privilege across cloud accounts.
- Administer and support Microsoft Entra ID and hybrid Active Directory identity services, including conditional access policies, multifactor authentication, authentication methods, application registrations, and single sign-on integrations.
- Configure and operate Microsoft Entra Privileged Identity Management (PIM) and support privileged access practices, just-in-time elevation, and periodic access reviews and certifications for sensitive roles and applications.
- Monitor, triage, and investigate cloud and identity security alerts from sources such as Wiz, AWS-native security services (GuardDuty, Security Hub, CloudTrail), Microsoft Defender for Cloud, Microsoft Entra ID Protection, and the enterprise SIEM.
- Contribute to secure cloud onboarding and architecture reviews for new cloud services, SaaS applications, and third-party integrations, including evaluation of authentication, authorization, logging, encryption, and data handling.
- Maintain familiarity with infrastructure-as-code and container technologies—such as Terraform or CloudFormation templates, CI/CD pipelines, and Kubernetes—sufficient to review security findings in these areas and route them appropriately.
- Serve as a well-rounded contributor across the broader security program, assisting with vulnerability management, data protection, application security, and endpoint and email security work as team priorities and organizational risk require.
- Serve as part of a dynamic team responsible for cybersecurity incident response, contributing to the detection, triage, investigation, containment, and remediation of security incidents, including cloud and identity-based attacks.
- Develop and maintain cloud and identity security metrics, dashboards, runbooks, and technical documentation for technical teams and leadership.
- Collaborate with teams throughout ISS, as well as Privacy and Compliance, to ensure the protection of ePHI and adherence to HIPAA and other regulatory requirements.
- Contribute to the development and implementation of cybersecurity strategies, policies, standards, and procedures, particularly those governing cloud and identity.
- Participate in a rotating on-call schedule to support incident response and time-sensitive security matters outside of standard business hours.
- Bachelor's degree or higher in Cybersecurity, Information Technology, or a related field is preferred; equivalent professional experience will be considered in lieu of a degree for the right candidate.
- Cloud certifications are highly desirable, particularly the AWS Certified Security – Specialty or AWS Certified Solutions Architect, and Microsoft certifications such as AZ-500 (Azure Security Engineer) or SC-300 (Identity and Access Administrator).
- Broad security certifications such as CompTIA Security+, GIAC GCLD (Cloud Security Essentials) or GCSA, or (ISC)² CCSP are also valued; progress toward or interest in a senior-level certification such as CISSP is viewed favorably.
- 3+ years of experience in cybersecurity, cloud engineering, identity and access management, or information technology with meaningful security responsibilities, in a large organization, preferably a large healthcare environment.
- Hands-on experience securing AWS environments, including a working understanding of IAM (roles, policies, trust relationships, permission boundaries), organizational structure and guardrails, VPC and network controls, S3 and data storage security, encryption and key management, and native services such as CloudTrail, GuardDuty, Security Hub, and Config.
- Working experience with Microsoft Azure and Microsoft 365 security, including Defender for Cloud, subscription and resource-level controls, and cloud workload protection.
- Some exposure to Google Cloud Platform is beneficial; deep GCP expertise is not expected, but general familiarity with a third cloud platform is a plus.
- Practical experience with a cloud security posture management or CNAPP platform such as Wiz, Prisma Cloud, Orca, or Microsoft Defender for Cloud, including interpreting findings, tuning policies, and using the platform to drive remediation.
- Solid working knowledge of Microsoft Entra ID and hybrid identity, including conditional access, multifactor authentication, Entra Connect and directory synchronization, application registrations and enterprise applications, SSO protocols (SAML, OAuth 2.0, OpenID Connect), and Privileged Identity Management.
- Understanding of core identity and access management concepts, including least privilege, role-based access control, separation of duties, joiner-mover-leaver processes, access reviews, and privileged access management.
- Familiarity with common cloud and identity attack techniques—such as credential and token theft, consent phishing, privilege escalation through misconfigured roles, and abuse of public or misconfigured cloud resources—and the controls that mitigate them.
- General familiarity with infrastructure-as-code (Terraform, CloudFormation), containers and Kubernetes, and CI/CD pipelines, sufficient to interpret security findings in these areas; hands-on development or pipeline ownership is not required.
- Well-rounded knowledge of cybersecurity domains beyond cloud and identity, including vulnerability management, data protection, application security, network security, and endpoint and email security, with the ability to contribute meaningfully outside the primary focus areas.
- Working knowledge of HIPAA and its requirements for protecting electronic protected health information (ePHI) in a hospital or healthcare environment, or the ability to develop that knowledge quickly.
- Hands-on experience contributing to cybersecurity incident response, including alert triage, investigation, containment, and remediation as part of a team.
- Scripting or automation experience with PowerShell, Python, or the AWS CLI, and comfort working with APIs to extract data and reduce manual effort, is a plus.
- Willingness and availability to participate in a rotating on-call schedule.
- Strong analytical and problem-solving skills, with the judgment to know when to dig deeper and when to escalate.
- Excellent communication and teamwork abilities.
- Ability to learn and adapt to new technologies quickly, which is essential given the pace of change in cloud and identity platforms.
- Ability to explain cloud and identity risk to application owners, infrastructure teams, and leadership in terms each audience can act on.
- Comfort contributing outside of the primary focus areas and shifting between workstreams as organizational risk and team needs change.
- Attention to detail and a proactive approach to security, particularly in environments that change continuously.
- Ability to support cybersecurity projects within a healthcare organization, balancing security objectives with clinical, operational, and regulatory priorities.
- Sound judgment in balancing security controls against the availability and usability requirements of clinical and business systems.
- Atlantic Health Morristown Medical Center, Morristown, NJ
- Atlantic Health Overlook Medical Center, Summit, NJ
- Atlantic Health Newton Medical Center, Newton, NJ
- Atlantic Health Chilton Medical Center, Pompton Plains, NJ
- Atlantic Health Hackettstown Medical Center, Hackettstown, NJ
- Atlantic Health Goryeb Children's Hospital, Morristown, NJ
- Atlantic Health CentraState Healthcare System, Freehold, NJ
- Atlantic Medical Group
- Atlantic Visiting Nurse
- Atlantic Mobile Health
- Atlantic Rehabilitation
We Have Received Awards And Recognition For The Services We Have Provided To Our Patients, Team Members And Communities. Below Are Just a Few Of Our Accolades
- Chosen for 17 years by Fortune as one of the magazine’s “100 Best Companies to Work For."
- Atlantic Health Morristown and Atlantic Health Overlook Named by Newsweek as two of the “World’s Best Hospitals” in 2026.
- Atlantic Health Morristown and Atlantic Health Overlook ranked within the top three hospitals in New Jersey by U.S. News & World Report’s 2025-2026 Best Hospital rankings.
- Atlantic Health scored four “A” grades by The Leapfrog Group in its Fall 2025 Hospital Safety Grades, performance measures reflecting errors, accidents, injuries and injections, as well as systems hospitals have in place to prevent harm.
- Atlantic Health Morristown and Atlantic Health Overlook are New Jersey's only hospitals to be named among America's 50 Best hospitals by Healthgrades in 2026.
- Named by Becker's Healthcare as one of the "165 Top Places to Work in Healthcare – 2026.
- Atlantic Health Morristown, Atlantic Health Overlook, Atlantic Health Chilton and Atlantic Health Newton all Forbes Top Hospitals for 2026.
- Named by Newsweek as one of America’s Greatest Workplaces for Inclusion & Diversity 2025.
- Atlantic Health rated LEVEL 9 - 2025 CHIME Digital Health Most Wired.
Team Member Benefits
- Medical, Dental, Vision, Prescription Coverage (22.5 hours per week or above for full-time and part-time team members)
- Life & AD&D Insurance.
- Short-Term and Long-Term Disability (with options to supplement)
- 403(b) Retirement Plan: Employer match, additional non-elective contribution
- PTO & Paid Sick Leave
- Tuition Assistance, Advancement & Academic Advising
- Parental, Adoption, Surrogacy Leave
- Backup and On-Site Childcare
- Well-Being Rewards
- Employee Assistance Program (EAP)
- Fertility Benefits, Healthy Pregnancy Program
- Flexible Spending & Commuter Accounts
- Pet, Home & Auto, Identity Theft and Legal Insurance
Note: In Compliance with the NJ Pay Transparency Act (effective Sunday, June 1, 2025), all job postings will include the hourly wage or salary (or a range), as well as this summary of benefits. Final compensation and benefit eligibility may vary by role and employment status and will be confirmed at the time of offer.
EEO STATEMENT
Atlantic Health, Inc. is an equal employment opportunity employer and federal contractor or subcontractor and therefore abides by applicable laws to protect applicants and employees from discrimination in hiring, promotion, discharge, pay, fringe benefits, job training, classification, referral, and other aspects of employment, on the basis of race, color, religion, sex (including pregnancy, gender identity and sexual orientation), national origin, citizenship status, disability, age, genetics, or veteran
About The Team
Atlantic Health System is at the forefront of medicine, setting standards for quality health care powered by a workforce of more than 18,000 team members and 4,800 affiliated physicians dedicated to building healthier communities, the system offers more than 400 sites of care, including eight award-winning medical centers. Specializing in cardiovascular care, cancer care, orthopedics, neuroscience, pediatrics, women's health and rehabilitation medicine. Atlantic Medical Group, comprised of 1,000 physicians and advanced practice providers, represents one of the largest multi-specialty practices in New Jersey and includes finance, legal, marketing, human resources, talent acquisition, ISS and more. Caring for our patients, our team members and the communities we serve is our central mission.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search